Legal

Privacy Policy

Last updated: July 2026

1Data controller

The controller of your personal data is [Legal entity] — [address] — VAT [•]. You can contact us about any privacy matter at support@roadly.it.

The controller's full identifying details will be added before the Service is offered for sale.

2Data we collect

  • Account data: email, name and user identifier, managed by our authentication system. We do not store passwords (sign-in via magic link only).
  • Usage data: technical information about your use of the Service, such as pages viewed, service selected, device and browser type, and technical logs needed for operation and security.
  • History and favorites: the items you mark as favorites and your playback history, kept to give you synchronisation across sessions (Neon database).
  • Payment data: we do NOT process or store payment card data, because payment does not happen on the site. The pass purchase is arranged via Telegram and payment is handled by the provider indicated there (PayPal), which processes your payment data as an independent controller under its own policy. Of the payment we keep only what we need to manage your access and meet accounting and tax obligations (for example confirmation of payment, amount, date and pass duration).
  • Free-trial and support requests: if you write to us on Telegram or through the site chat, we process the content of your message and the contact details you give us (for example your Telegram username or email) in order to reply and, where appropriate, enable the trial.

We do not collect, transmit or store the third-party content you play: the IPTV lists and source credentials you connect are processed only to give you access to your own content.

3Legal bases (GDPR)

  • Performance of the contract (Art. 6.1.b GDPR): account creation, delivery of the Service, subscription and payment management.
  • Legitimate interest (Art. 6.1.f GDPR): security of the Service, abuse prevention, technical improvement.
  • Consent (Art. 6.1.a GDPR): any non-strictly-necessary cookies or analytics tools, where enabled.
  • Legal obligations (Art. 6.1.c GDPR): tax and accounting obligations relating to payments.

4Sub-processors

To deliver the Service we rely on third-party providers who process data on our behalf:

  • Neon — database and storage of account data (email, name, history, favorites).
  • Brevo — delivery of sign-in emails (magic link).
  • Oracle Cloud — application hosting and streaming.
  • PayPal — payment processing.
  • PostHog (EU instance) — technical usage measurement and error diagnostics for the Service.

Some of these providers may process data outside the European Union. In such cases transfers are made in compliance with the GDPR, on the basis of Standard Contractual Clauses (SCC) approved by the European Commission or other appropriate safeguards.

5Data retention

We keep data for as long as necessary to provide the Service and to comply with legal obligations. Account and usage data are kept for as long as your account remains active and deleted or anonymised within a reasonable time after the account is closed, save for retention obligations (for example accounting and tax).

6Your rights and contact

You have the right to access your data, request its rectification or erasure, restriction of or objection to processing, and data portability. You may also withdraw consent at any time and lodge a complaint with the data protection supervisory authority.

To exercise your rights, write to us at support@roadly.it. We will respond within the time limits set by law.

7Cookies

We use cookies and similar technologies that are strictly necessary for the Service to work (for example for authentication and to keep your session). These technical cookies do not require consent.

Should we introduce analytics or measurement tools that are not strictly necessary, we will enable them only with your prior consent through a dedicated banner, in line with applicable law.

8Minors

The Service is not intended for anyone under 18. We do not knowingly collect data from minors. If you believe a minor has provided us with data, contact us and we will delete it.

9Your Google account data (YouTube and Google Drive)

If you choose to connect your Google account, Roadly accesses only the Google data needed for the features you enable, and nothing else:

  • YouTube (youtube.readonly scope, read-only): your YouTube account information — such as subscriptions and playlists — used solely to show your home and your content inside Roadly. We do not post, modify or delete anything on your account.
  • Google Drive (drive.file scope): access is limited to only the files you open or select in Roadly. We do not access the rest of your Drive.

Who we share it with: we do not sell, transfer or disclose your Google account data to third parties for their own purposes. It is processed only to provide the features you requested, on our infrastructure and by the sub-processors listed in Section 4, which act solely on our behalf and under our instructions. We do not use this data for advertising or to train artificial-intelligence or machine-learning models. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we protect it: your Google access tokens are stored in protected form on our servers and transmitted only over encrypted connections (HTTPS/TLS); they are not exposed in the browser beyond what is strictly necessary. You can revoke access at any time, by disconnecting the account in Roadly or from your Google account's Permissions page: upon revocation we stop all access and the tokens are deleted.

10Security measures

We apply appropriate technical and organisational measures to protect personal data, with particular care for sensitive data such as access tokens for connected services and the credentials of the sources you connect:

  • Encryption in transit: all communication with the Service uses HTTPS/TLS.
  • Protection at rest: sensitive data is stored in protected form; the credentials of the sources you connect (for example IPTV) are encrypted with a dedicated key.
  • Access control: access to data requires authentication and is restricted; application secrets are never included in the code that runs in the browser.
  • Minimisation: we request only the minimum scopes needed for the features offered.
  • Revocation and deletion: you can disconnect connected services at any time; on disconnection the related tokens and credentials are deleted.

11Changes to this policy

We may update this policy. In case of material changes we will notify you. Please review this page from time to time to stay informed about how we process your data.